
PSCF
OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

OWASP Thick Client Application Security Verification Standard

Centralized YAML-based knowledge base linking MITRE CWE, OWASP Top10, ASVS, and other security standards with versioned references. Includes MkDocs…

Software Component Verification Standard (SCVS)

Interactive platform linking security standards and guidelines for designing, developing, testing, and procuring secure software. Provides a unified…

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

Structured playbook for integrating threat modeling into product security, covering stakeholder buy-in, organizational embedding, training, process…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.


The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

The Secure Coding Practices Quick-reference Guide from OWASP

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory